Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)O
Posts
3
Comments
999
Joined
6 mo. ago

  • Okay, sure, but if you're trying to build a verifiable, FOSS web script, you can just avoid using any of that obfuscation.

  • Every line of client-side code on every website is fully visible to the user every time it runs. All you have to do is right click and select 'view page source'.

  • But as a web page, it would be delivered by the web server, requiring you to trust that the server is not snooping on your decrypted content

    Anybody interested (and capable) enough could view the web page's source and verify that the scripts running on it are identical to what they're supposed to be, and if they want to, they can even go through the entire code line-by-line to verify.

    Honestly, web scripts are easier to verify than a browser extension or stand-alone app, because you can quickly and easily view the (local) source code that you're actually running.

    I'd say that browser extensions and apps are more difficult to verify. You can, of course, publish the source code, but unless end users are compiling it from source every time, you have an issue with them having a difficult time verifying that the compiled code they download and run is actually the same as the publicly visible source code. A malicious developer could publish clean source code, but then provide compromised compiled versions for download and install.

    I suppose there is a frequency argument to be made, though. With a browser extension or standalone app, you only need to check and re-verify the code each time it's updated. But a script running on a web page would need to be verified every time you use it.

  • So make sure everything is encrypted before it's ever sent to the host, which is verifiable through the open source code running on your own PC.

    If your local software doesn't send anything in plaintext and doesn't ever send the encryption key, then it doesn't matter what software the host is running -- they won't be able to decrypt the content. Even if they're actively trying to breach the encryption, they're not really any better off than just some random man-in-the-middle sniffing network packets.

  • You don't need a browser extension or an app for this.

    Look at MEGA Upload for example. While it's primarily a cloud storage platform, it does allow for file/content sharing ... though not really in the social media kind of way I think you're getting at. But the technical way they implement it could help you.

    When you sign up there, you set a password, and the hash of that password is then your encryption key. All your client (whether an independent app or just a script on a web page) needs is the ability to hash the user's password to be able to reconstruct the key and begin decrypting things.

    The main weakness of this is that users must remember their own password. Due to the zero-knowledge encryption, the host cannot know the password and cannot recover it. So if the user forgets their password, then they're just shit out of luck, and all their content is forever inaccessible.

  • "When we tried to turn him back on, he wouldn't reboot. Aw, shucks."

  • Require resumes and applications to be submitted on paper, either in person or by mail.

    Suddenly, the thousands of frivolous applications will vanish, and only a few serious ones will remain.

    Seriously, the solution to this entire fucking problem is paper.

  • Have we tried turning Elon off and then on again?

  • He's got my vote.

  • widespread surveillance

    Every fucking corpo website is a platform for widespread surveillance. Best you can do is use a VPN and noscript.

    and IP theft.

    That part is based. Intellectual property, like most property, is theft.

  • You need to learn the ways of the dumpster:

    A) Find the good dumpsters. Some grocery stores have 'compost only' dumpsters, and those are an absolute gold mine. Those ones will be full of food and only food.

    B) Of course you need to wash everything thoroughly before eating it. And don't take (unwrapped, unsealed) things that can't be washed.

    C) Follow your nose. Billions of years of evolution have actually equipped you pretty well when it comes to determining which food is and isn't safe to eat. If it looks good and smells good, it probably is good. Add a bit of common sense and looking out for signs of a few of the more dangerous things -- like botulism -- and you're pretty well safe. Also pay attention to recent recalls -- if the store is throwing away lots of the same thing, and none of it is expired yet, check for recalls on that product before eating it. (And look at why it was recalled. Recalled stuff is sometimes still perfectly safe to eat. Lots of recalls happen for reasons such as the product being mislabeled and not mentioning an allergen that might be present. In that case, as long as you're not allergic to that particular thing, you're good.)

    I've never once gotten sick from eating dumpster food. IMO, unless you have some specific health condition that puts you at higher risk, you're very unlikely to have problems.

  • Removed Deleted

    Today's online debating

    Jump
  • Most people don't do that.

  • Legit, yes.

    Went to the local hardware store yesterday to pick up some necessary nuts and bolts for building a bicycle trailer (itself being built so I don't have to spend money on gas as much). And fully half of those nuts and bolts went into my pockets instead of the little bag they give you to go through the checkout. The more expensive half, of course.

    Until the Epstein class is behind bars -- or better yet, 6ft underground -- I will continue to do everything possible to keep my money out of their pockets, which includes stealing things when feasible.

  • But, also, beef is pretty much the worst meat when it comes to environmental impact of producing it. So it probably should be the most expensive.

  • and unfortunately most fresh produce at this point

    Special secret: grocery store dumpsters are often full of perfectly good fresh produce -- and I mean full. And in most states, it's perfectly legal to take some. Learn the ways of the dumpster, and you'll eat like a king.

  • that’s almost old enough to get a driver’s license itself

    Bruh. As far as I'm concerned, a car under 20 years old is a huge luxury.

  • E V E R Y T H I N G

  • In the conservative mindset, any person under 18 is the property of their parents, which they can do whatever the fuck they want with.

  • Sure, you get a free "pillow".

    (Actually a lumpy bag of industrial waste foam cutoff pieces.)

  • Ask Lemmy @lemmy.world

    Are pay-by-the-minute phone plans a thing of the past? (US)

  • Dullsters @dullsters.net

    Installed a mini-split heat pump for the first time